Notifications
Clear all

Stegbreak

15 Posts
5 Users
0 Reactions
5,119 Views
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

I am using stegbreak in Windows on a file that stegdetect found to have hidden data. But I get an error when attempting to use stegbreak stating that

stegbreak -t p 8.jpg
fopen /usr/local/share/stegbreak/rules.ini No such file or directory

Of course that directory doesnt exist I am using windows. Does anyone know a work around or another soluiton for this?


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Google? I did a quick search and found several posts w/ solutions…


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

What did you search for can you provide a link.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

www.google.com

stegbreak rules.ini


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

I guess I just cannot find it. Anyways I will just put it in a Linux and do it like that probably faster anyways.

Thanks for your help.


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

gtorgersen,

As you're running stegbreak in Windows do you not have to pass the location of the "rules.ini" file? Such as

stegbreak -r rules.ini -t p 8.jpg

And this would indicate that "rules.ini" file is in the current working directory?

Cheers!

farmerdude

www.forensicbootcd.com

www.onlineforensictraining.com


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

I figured it out. Thanks for the help.


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

Another questions. Everytime I run the command

stegbreak -r RULES.ini -t p -c "FILE PATH"

I get an output of a .jph file. What is this file and how do I know if the application was successful in breaking the password?


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I figured it out. Thanks for the help.

Care to share?


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
Topic starter  

Sure gtorgersen@dsionline.biz and we can do it offline. We will report our finds back to anyone who is interested when done.


   
ReplyQuote
Page 1 / 2
Share: